Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
14.316 exploits
GitHub PoC
FzRsLLaSheR/CVE-2026-14960-CVE-2026-14961
CVE-2026-14960CRITICAL15 jul 2026
CVE-2026-14960
48RIESGO
abrir
GitHub PoC27
This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing the Erlang protocol expected by localhost:1050 and tunneling it through the websocket for file r/w and arbitrary code execution via RPC calls.
CVE-2026-15409CRITICALbajo ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC2
Raimu0x19/CVE-2026-13001
CVE-2026-13001CRITICAL15 jul 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
63RIESGO
abrir
GitHub PoC3
CVE-2026-15409
CVE-2026-15409CRITICALbajo ataqueransomware15 jul 2026
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A
100RIESGO
abrir
GitHub PoC
CVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
CVE-2026-43499HIGH15 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC
My portfolio showcasing vulnerability research (CVE-2026-11989, CVE-2026-11395) and automated threat orchestration engineering (Lucius Engine, TalonVigil).
CVE-2026-11989MEDIUM15 jul 2026
Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping
33RIESGO
abrir
GitHub PoC
arpit-bansal15/cve-2026-48282-pentest-lab
CVE-2026-48282CRITICAL15 jul 2026
ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
85RIESGO
abrir
GitHub PoC2
CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).
CVE-2026-58138CRITICAL15 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
GitHub PoC
seqra/cve-2026-58138
CVE-2026-58138CRITICAL15 jul 2026
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
63RIESGO
abrir
GitHub PoC
Panduan mitigasi Januscape (CVE-2026-53359) AlmaLinux 9.5 production-safe + scripts
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC
A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free vulnerability in the KVM code that has been sitting there since 2010.
CVE-2026-53359HIGH15 jul 2026
KVM: x86: Fix shadow paging use-after-free due to unexpected role
41RIESGO
abrir
GitHub PoC28
PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation
CVE-2026-58635HIGH15 jul 2026
Windows Narrator Braille Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
CVE-2026-15410 - More: https://github.com/HORKimhab/poc-cve-collection
CVE-2026-15410HIGHbajo ataqueransomware15 jul 2026
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the S
93RIESGO
abrir
GitHub PoC
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization
CVE-2026-59827CRITICAL15 jul 2026
Metabase: Unsafe Deserialization of H2 Query Results
48RIESGO
abrir
GitHub PoC
Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data destruction (fixed in 4.14.8/4.18.3/4.21.0)
CVE-2026-46587HIGH15 jul 2026
Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input
41RIESGO
abrir
GitHub PoC
exploit for CVE-2022-42889
CVE-2022-4288915 jul 2026
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
60RIESGO
abrir
GitHub PoC
A containerized enterprise-style lab for researching and defending against CVE-2026-27483.
CVE-2026-27483HIGH15 jul 2026
MindsDB has Path Traversal in /api/files Leading to Remote Code Execution
61RIESGO
abrir
GitHub PoC
firstlax6t/CVE-2026-36669-FengOffice
CVE-2026-36669CRITICAL15 jul 2026
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote
48RIESGO
abrir
GitHub PoC
lamaper/CVE-2026-52199
CVE-2026-52199CRITICAL15 jul 2026
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/
48RIESGO
abrir
GitHub PoC3
A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).
CVE-2024-6387HIGH15 jul 2026
Openssh: regresshion - race condition in ssh allows rce/dos
63RIESGO
abrir
GitHub PoC8
A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.
CVE-2026-23744CRITICAL14 jul 2026
REC in MCPJam inspector due to HTTP Endpoint exposes
75RIESGO
abrir
GitHub PoC
asoka666/Cve-2020-11023
CVE-2020-11023MEDIUMbajo ataque14 jul 2026
Potential XSS vulnerability in jQuery
85RIESGO
abrir
GitHub PoC
CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan integration and modern GUI.
CVE-2026-8181CRITICAL14 jul 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
68RIESGO
abrir
GitHub PoC1
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
CVE-2026-26718CRITICAL14 jul 2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att
48RIESGO
abrir
GitHub PoC
Log4j Vulnerability homelab
CVE-2021-44228CRITICALbajo ataqueransomware14 jul 2026
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir
GitHub PoC2
will be published
CVE-2026-15706CRITICAL14 jul 2026
Missing Authentication for Critical Function in Management API in Baylan Water Meters's BMS
48RIESGO
abrir
GitHub PoC
Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework
CVE-2011-252314 jul 2026
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
GitHub PoC
本次个人漏洞研究进展成果
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC65
Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir
GitHub PoC8
Bartixxx32/CVE-2026-43499-OnePlus15
CVE-2026-43499HIGH14 jul 2026
rtmutex: Use waiter::task instead of current in remove_waiter()
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.